Skip to content

Conversation

@davehadley
Copy link
Collaborator

@davehadley davehadley commented Dec 19, 2025

Currently, postgres secrets are randomized at helm install time. This is secure, however, can lead to problems recovering in cases where the cluster experiences unplanned down time. For example, see the incident report at:
https://dlsltd.sharepoint.com/:w:/s/Workflows/IQAeKijFhDqOT4adurvgibS4AVgjeK0bgzZstcE1tmf5T-A?e=3l6NGx
This PR replaces the randomized passwords with static SealedSecrets.

@davehadley davehadley force-pushed the drh/stable-database-passwords branch 4 times, most recently from 98e333a to bc9dd3b Compare December 19, 2025 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants